Nikhil Mathur*
Introduction
Corporate fraud is one of the most significant challenges confronting modern economies as it affects not only the corporation itself but also the investors, creditors, consumers, financial institutions and other stakeholders. The growing complexity of corporate organisations, coupled with digitalisation and the increasing use of artificial intelligence, has enabled sophisticated forms of fraudulent activities, making their detection, investigation and attribution a difficult piece of work.
Corporate fraud is a broad term encompassing a wide range of dishonest practices, including fraud committed by a person acting for or on behalf of a corporation with the intention of obtaining an unlawful advantage for the organisation. In this type of fraud, the criminal liability of the individual wrongdoer is generally undisputed, but what will be the liability of the corporation in such a case for whose benefit the individual takes the risk of committing fraud? Whether a corporation, as an artificial legal person, should also incur criminal liability.
Attribution of Corporate Criminal Liability
The above issue may be answered by analysing two distinct situations within such corporate fraud –
The first one relates to fraud committed by those who constitute the corporation’s controlling mind, that is, the directors, chief executive officers and other members of senior management.
The second concerns fraud committed by employees (other than those falling within the first category), agents, consultants, contractors or other persons acting for or on behalf of the corporation who do not control its affairs but whose conduct is nevertheless intended to benefit the organisation.
While both situations involve fraud committed for the corporation’s advantage, they raise fundamentally different questions regarding the attribution of corporate criminal liability.
Situation 1
The first situation is governed by the identification doctrine developed under English law, according to which the acts and mental state of the corporation’s ‘directing mind and will’ are attributed to the corporation itself. Indian jurisprudence has likewise recognised this attribution principle through a series of decisions of the Supreme Court.
In the case of Standard Chartered Bank v. Directorate of Enforcement (2005) 4 SCC 530, the court, by majority, overruled the Velliappa case and held that a corporation is capable of being prosecuted for a criminal offence despite being incapable of undergoing imprisonment. This case provides clarity on the issue that a corporation cannot escape liability only because the punishment for the offence includes mandatory imprisonment along with a fine. In such a case, punishment in the form of a fine only would suffice.
Where the Standard Chartered case decides that the corporation can be held criminally liable, in Iridium India Telecom Ltd. v. Motorola Inc. (2011) 1 SCC 74, the court answers the question with respect to corporate liability where fraud was committed by the controlling mind of the corporation. In this case, the court observed that the definition of ‘person’ under the Indian Penal Code, 1860 (now Bharatiya Nyaya Sanhita, 2023) and the General Clauses Act, 1897 includes both the natural person as well as a juristic person. A corporation, being a juristic person, is not capable of forming mens rea by itself, but the mens rea of the person who committed the fraud may be attributed to it if the person who committed the fraud in relation to the business of the corporation has such deep control over the company that his acts look like acts of the corporation. Thus, the individual mental state is not treated as something the corporation independently possesses; rather, it is legally attributed to the corporation, enabling its prosecution and conviction in the same manner as against any natural person.
The Court further reiterated the observation made in the Standard Chartered Bank case and held that where a statute mentions both mandatory imprisonment along with a fine as punishment, only a fine will suffice in the case of a corporation.
A very important observation was made by the Supreme Court in the case of Sunil Bharti Mittal v. CBI (2015) 4 SCC 609, that only the acts and mental state of the corporation’s controlling mind may be attributed to the corporation; the reverse does not automatically follow. Corporate criminal liability does not by itself render directors or promoters personally liable. Directors cannot be prosecuted merely because of their position unless there is independent evidence of their personal involvement or the governing statute specifically provides otherwise.
It can be concluded from the above-mentioned decisions of the Supreme Court that the acts and relevant mental state of a director, chief executive officer or other member of senior management who is the controlling mind of the corporation may be attributed to the corporation. However, the reverse is not true, and the controlling mind cannot be held automatically liable in case of fraud by a corporation.
Situation 2
The second situation is more complex in nature, as here fraud is not committed by the controlling mind of the corporation but by one operating below them to whom certain powers are delegated. In this case, the attribution of liability upon the corporation for fraud is very difficult, as the person who committed the act is not the controlling mind of the corporation, though he committed the fraud for the benefit of the organisation.
The question therefore is whether criminal liability should remain confined to the individual wrongdoer (who is not the controlling mind) or if accountability of the corporation must also be fixed for whose benefit corporate fraud was committed.
The UK’s Shift Towards Preventive Corporate Liability
It was this accountability gap that prompted legislative reform in the United Kingdom through the introduction of a distinct corporate offence of “Failure to Prevent Fraud” under sections 199 to 206 of the Economic Crime and Corporate Transparency Act, 2023 (ECCTA) (hereinafter referred to as the Fraud Prevention Model). This Fraud Prevention Model is not replacing the Identification Doctrine but supplements it by addressing circumstances where fraud is committed by persons who are not the controlling mind but are acting for or on behalf of the organisation for the benefit of such an organisation. This reform made seniority no longer the only basis for attributing liability to the corporation and thus fixed an accountability gap.
This new offence in the UK is not introduced in haste just to punish corporations but is a deliberate act of the legislature, where they restrict the applicability of the Act only to large organisations where specified fraud is committed by an associated person with the intention to provide benefit to the organisation. It is not important here that the corporation actually received some benefit. Intention to provide benefit is sufficient.
Liability here is not absolute, and an organisation may still prevent it by demonstrating that it had reasonable fraud prevention procedures in place or that, having regard to the nature and circumstances of the business, it was unreasonable to expect such a procedure. Therefore, the emphasis of the Act was not merely on punishing corporate misconduct but on encouraging organisations to embed effective compliance systems capable of preventing fraud before it occurs.
Thus, this new change reflects a significant shift from a purely attribution-based model to one founded on preventive corporate responsibility by encouraging organisations to actively manage fraud risks instead of responding only after misconduct has occurred. The legislation seeks to strengthen both corporate governance and public confidence at the same time.
Should India Introduce a Failure to Prevent Fraud Offence?
There is no doubt that India possesses a robust mechanism to combat corporate fraud. The Companies Act, 2013, contains stringent provisions dealing with fraudulent conduct by corporations and their officers. The Bharatiya Nyaya Sanhita, 2023, criminalises several forms of economic offences that may arise in a corporate context. In addition, there is a regulatory body, the Securities and Exchange Board of India (SEBI), that issues guidelines from time to time for companies to maintain the best ethical practices. There are also specialised bodies like the Serious Fraud Investigation Office (SFIO), Enforcement Directorate (ED) that, along with SEBI, play an important role in the investigation and prosecution of corporate misconduct. Therefore, mere absence of a specific failure to prevent fraud like offence cannot by itself be regarded as a deficiency in Indian law.
The real distinction lies in corporate responsibility recognised under the existing legal framework; that is, where Indian law primarily operates after fraudulent conduct has occurred by identifying the offender and imposing criminal sanctions, it does not generally impose a proactive obligation upon corporations to establish reasonable systems capable of preventing fraud committed by persons acting for or on their behalf. The Companies Act, 2013 contains several provisions addressing fraudulent conduct, including Sections 36, 75, 251, 339, and 447, but in order to prevent fraud by a person who is not the controlling mind of the corporation, there is no obligation imposed on the corporation. Similarly, the Bharatiya Nyaya Sanhita, 2023 also criminalises fraudulent conduct but does not provide a mechanism to prevent corporate fraud. Further, employment alone does not ordinarily create vicarious criminal liability unless the law specifically provides for it.
Thus, the failure to prevent fraud offence seeks to address this gap by shifting focus from punishment to prevention of fraud. Rather than concentrating only on fixing liability after fraud has occurred, it encourages organisations to establish effective compliance systems, strengthen internal controls and cultivate a corporate culture that discourages fraudulent conduct.
Nevertheless, the UK’s Fraud Prevention Model should not be superimposed on the Indian scenario without careful adaptation (See Figure 1 below). India’s corporate culture is very diverse, comprising not only large listed companies but also micro, small and medium enterprises. Therefore, careful analysis of them along with the UK’s Fraud Prevention Model is necessary to create a model perfect not only for attributing liability to the corporation in case of fraud but also for creating an obligation on such a corporation for the prevention of corporate fraud. For example, like the UK, should India also restrict the application of the offence only to large organisations, or can it be modified and include medium enterprises also is a question that needs to be studied first, or whether the guidelines on which companies should make their compliance system with changes suitable to their corporate structure for the prevention of fraud are all the things that need a careful study. Further imposing identical compliance obligations on every organisation could result in a disproportionate financial and administrative burden. Any legislative reform must therefore balance stronger corporate accountability with the practical realities of the Indian corporate environment.

Conclusion
India may benefit from the preventive philosophy underlying the UK’s Fraud Prevention Model under ECCTA 2023 by not reproducing such a model in its entirety but should adjust it as per the corporate environment existing in India. The offence must be designed in such a manner that its applicability is justified primarily to organisations whose size and operations justify enhanced compliance obligations and are supported by a statutory defence based on reasonable fraud prevention procedures, which would strengthen corporate accountability while maintaining proportionality. Such an approach would complement the existing legal framework by encouraging corporations to prevent fraud through effective governance, robust compliance systems, and meaningful internal controls instead of relying solely on criminal sanctions after the misconduct has already occurred.
* The author has completed an LL.M. from Jai Minesh Adivasi University and holds an LL.B. from Campus Law Centre, University of Delhi. The author may be contacted at mathurn218@gmail.com.
This blog reflects the personal views of the author and does not necessarily represent the views of The Policy Chronicle.